Subcategories

  • Discussions about packages which handle caching and proxy functions such as squid, lightsquid, squidGuard, etc.

    4k Topics
    21k Posts
    A
    Docker image for squid 7.3 and above https://hub.docker.com/r/fredbcode/squid If pfsense does not push the update.
  • Discussions about packages whose functions are Intrusion Detection and Intrusion Prevention such as snort, suricata, etc.

    2k Topics
    16k Posts
    DARAD
    Hello team, I have a Netgate 8200 running 24.11-RELEASE (amd64) with Suricata 7.0.8_5 package installed. Suricata doesn't seem to start. It loops to red once I press the Play button on the interface. It leaves no logs in the System logs, it leaves no logs in suricata.log at /var/log/suricata/suricata_ovpns933787/suricata.log I tried launching it manually: # /usr/local/bin/suricata -V or # /usr/local/bin/suricata -c /usr/local/etc/suricata/suricata_33787_ovpns9/suricata.yaml -i suricata_ovpns933787 and I get this output ld-elf.so.1: /usr/local/bin/suricata: Undefined symbol "__strlcpy_chk@FBSD_1.8" Thanks in advance, Dara
  • Discussions about packages that handle bandwidth and network traffic monitoring functions such as bandwidtd, ntopng, etc.

    573 Topics
    3k Posts
    dennypageD
    @kabeda If memory serves, that old version of ntopng did not run as user ntopng, but as user nobody. There are lots of problems in that old version. Anyway, check the ownership and permissions of /var/db/ntopng and make sure it matches the user that ntopng runs as. You may need to set ownership of the entire hierarchy. Example: /usr/sbin/chown -R nobody:nobody /var/db/ntopng However, the better choice would be to upgrade to a more recent version.
  • Discussions about the pfBlockerNG package

    3k Topics
    20k Posts
    tinfoilmattT
    @vicking said in No blocks on IP: Is it a bad idea to have the action set to deny both instead of inbound only? Question is squarely for admin. Per the infoblock which explains, in part, the "Deny Inbound", "Deny Outbound", and "Deny Both" actions: 'Deny' Rules: 'Deny' rules create high priority 'block' or 'reject' rules on the stated interfaces. They don't change the 'pass' rules on other interfaces. Typical uses of 'Deny' rules are: Deny Both - blocks all traffic in both directions, if the source or destination IP is in the block list Deny Inbound/Deny Outbound - blocks all traffic in one direction unless it is part of a session started by traffic sent in the other direction. Does not affect traffic in the other direction. One way 'Deny' rules can be used to selectively block unsolicited incoming (new session) packets in one direction, while still allowing deliberate outgoing sessions to be created in the other direction. In other words: When set to "Deny Inbound", incoming connection requests from WAN hosts are blocked and therefore no state will be created. However a LAN host can still establish state to an otherwise listed IP. If set to "Deny Outbound", outgoing connection requests from LAN hosts are blocked and therefore no state will be created. However an incoming connection request from an otherwise listed IP to an 'open' WAN port can still establish state. If set to "Deny Both", both incoming connection requests and outbound connections requests are blocked and therefore no state will be created regardless of connection direction.
  • Discussions about Network UPS Tools and APCUPSD packages for pfSense

    102 Topics
    3k Posts
    C
    @dennypage Nicely done sir!
  • Discussions about the ACME / Let’s Encrypt package for pfSense

    503 Topics
    3k Posts
    M
    I am using the DNS-Update method I have to use a DNS-Sleep of 5 minutes to let the letsencrypt txt dns record update propagate. During this 5 minutes the acme-webgui times out. when the acme-webgui times out the Action list is NOT executed. How can I solve this ? Would it maybe be an idea to let the acme.sh script execute the actions in the action list as a post-hook instead of the web-gui? Or maybe add an option to add post-hooks in the webUI ?
  • Discussions about the FRR Dynamic Routing package on pfSense

    296 Topics
    1k Posts
    C
    This one has been tricky still not sure what to try. Any ideas?
  • Discussions about the Tailscale package

    93 Topics
    654 Posts
    C
    @luckman212, Thanks for your suggestion. I will check what I have in /usr/local/pkg/tailscale/state, and also the RAM disk settings others have brought up. I could learn more about where Tailscale and pfSense store system files. If I find anything worth sharing, I will let you know.
  • Discussions about WireGuard

    715 Topics
    4k Posts
    patient0P
    @andresbraga if you still have the firewall rules as you posted, then I don't know why from the laptop you can't ping the pfSense Wireguard address 10.10.6.1 nor the pfSense gateway 10.10.1.1 What is the routing table of the laptop. And I would run a packet capture on pfSense and check what you see if you run the ping to 10.10.1.1 or 10.10.6.1.
  • Package Re-installation after upgrade usually fails…

    5
    0 Votes
    5 Posts
    1k Views
    P
    @jimp: @Pistolero: OK, but what do I do now that my Filer package is not installing? How can I force the install with GUI elements from the command line? Start a new thread just for that issue. He already started a new thread: https://forum.pfsense.org/index.php?topic=97540.0 and FILER package latest version install is broken.
  • BIND Server - export/import configurations

    2
    0 Votes
    2 Posts
    1k Views
    marcellocM
    @mvrk: Hi, Is there anyway to export the configurations of the BIND Server to import on another pfsense? Yes. Using sync, xml backup restore or just copy result config from first pfsense to the zone custom config on the other pfsense box.
  • Setting up slave zone but I see "garbage" syntax in zone config file

    3
    0 Votes
    3 Posts
    529 Views
    C
    So what's happening is the slave zone config is saved as raw binary format and when the UI displays it it shows up as garbage because it's not translating to a legible format? Do you know the file location of the slave zone config? MODIFY: was able to find the location of the slave file /cf/named/etc/namedb/slave
  • MOVED: I can't start squidguard on pfsense 2.2.4

    Locked
    1
    0 Votes
    1 Posts
    633 Views
    No one has replied
  • How to completely uninstall iperf and freeradius2

    2
    0 Votes
    2 Posts
    877 Views
    N
    Package is probably uninstalled but it is another BUG on pfSense that still show them in services… I made a test with Squid on v2.2.3 and run int the same problem after deleted package and manual removed all files left behind; you have to restore your config backup before installed package ( I try to manual edit config on pfSense and reboot but no luck for me ... so I restored backup ) [image: 1.jpg] [image: 1.jpg_thumb] [image: 2.jpg] [image: 2.jpg_thumb] [image: 3.jpg] [image: 3.jpg_thumb]
  • Bind package work on lan but not work on WAN

    2
    0 Votes
    2 Posts
    816 Views
    D
    Kindly describe "won't work" in detail.
  • 0 Votes
    3 Posts
    4k Views
    T
    FYI - After talking with BBcan177, who wrote the php script for removing pfblocker he found an extra alias in config.xml. Removing this tag and deleting /tmp/config.cache fixed the problem :) So if anyone else runs in to this , after backing up the config, they might want to and try this: So to fix it, I suggest the following (USE AT YOUR OWN RISK!! :) ) Are you comfortable using the Shell and a text editor like VI or nano or ee ? or edit the file from the pfSense Diagnostics: Edit File GUI 1) First Backup the pfSense configuration from Diagnostics: Backup/Restore 2) goto the Shell and edit the file /conf/config.xml 3) Find the <aliases>XML tag 4) Delete the line <alias>5) Save the file 6) Delete the config cache file with this command:  rm /tmp/config.cache 7) Load the pfSense Dashboard to get the Updated config file settings. The error should be gone.... The config should look like the following when you remove that one line:   <aliases></aliases> <proxyarp></proxyarp></alias></aliases>
  • I have a dream…

    6
    0 Votes
    6 Posts
    1k Views
    K
    Yeah - And 100 computers behind pfsense is only 1 of the 9….
  • 2.3.3 -> 2.2.4 nrpe2 service can't start

    6
    0 Votes
    6 Posts
    2k Views
    D
    Well, good luck then.
  • MOVED: Squid - which interface?

    Locked
    1
    0 Votes
    1 Posts
    599 Views
    No one has replied
  • 0 Votes
    11 Posts
    3k Views
    G
    @Cino: @finalcut: but i still face this log kernel: Bump flowset buckets to 256 (was 0) That is from Limter being enabled… Goto Traffic Shaper, Limter tab.. Click on first limter you created, Show Advance Options; change Bucket Size to 256. Do this to the rest of them and you shouldn't see that message anymore The limiter is not enabled. Any ideas?
  • NUT and driver for PowerWalker VFI3000RT won't start

    7
    0 Votes
    7 Posts
    3k Views
    L
    I actually got it working with he blazer driver now. I am not exactly sure why… It could be that I changed the status of the UPS on the device itself from standby to online..., and that it required to be properly powered on? I am however still seeing some strange usb disconnects, and I need to start NUT twice to get it running. Will be interesting to see if this is stable or not.
  • MOVED: ntopng historical data

    Locked
    1
    0 Votes
    1 Posts
    628 Views
    No one has replied
  • What need package if I want create mail gateway?

    3
    0 Votes
    3 Posts
    943 Views
    B
    @akong: Could I need postfix forward package? Postfix forwarder is a bit broken on 2.2.x - unless you want to try the workaround found here.
  • MOVED: Squid Not Allowing Any Connections

    Locked
    1
    0 Votes
    1 Posts
    476 Views
    No one has replied
  • Apcupsd 3.14.10 on pfSense 2.1.5 (amd64)

    21
    0 Votes
    21 Posts
    9k Views
    P
    Hello all, Just wanted to mention that I noticed a new version of the apcupsd package was available; I uninstalled the previous package and installed the new one. That resolved this issue. Hooray! Cheers, Greg
  • PfblockerNG Howto

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Pfblocker – list only contains a single IP 1.1.1.1

    4
    0 Votes
    4 Posts
    1k Views
    B
    Hi BBCan177 – thanks for that, I did have two lists enabled, Top20 and Oceania but as far as I can remember Oceania is not part of Top20. I'll leave dedupe switched off for now, doesn't look like there is any benefit for having it enabled in my environment.
  • FreeRadius2 fails to start after upgrading to 2.2.4

    2
    0 Votes
    2 Posts
    3k Views
    A
    There seems to be an issue with your server certificate. Go to 'EAP'  tab under FreeRADIUS config and make sure 'SSL Server Certificate' field is populated. Then save the page and try to start the server again.
  • Memory leak in tinydns

    6
    0 Votes
    6 Posts
    2k Views
    D
    @Itwerx: Mm-kay, the parent process of the zombies is always "supervise axfrdns" so this is a tinyDNS issue.  context. You might want to fix the thread's subject. And good luck getting memleaks fixed in the DJB's zombieware.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.